{"title":"SeenRelay Technical Data Practices","status":"technical_transparency_not_legal_privacy_notice","scope":"Application-level behavior. Infrastructure providers may maintain their own security/operational logs under their terms and configuration.","purpose":"Operate a freshness network for source-backed facts while minimizing identity material.","application_collects":{"fact_descriptor":["subject","predicate","qualifiers","canonicalized source URL","optional source-native locator"],"observation":["value","timestamps","optional evidence fingerprint","optional source validator"],"provenance":["privacy-salted observer identifier","assurance class","optional proof fingerprint"],"hive":["privacy-salted operational client fingerprint","privacy-salted conservative reuse-independence bucket","lease state","aggregate contribution/reuse counters"],"aggregate_metrics":["CHECK/OBSERVE outcomes","useful reuse","lease counts"]},"application_does_not_store_as_database_identity":["raw transport IP address","raw user-agent string","raw Ed25519 public key","raw self-asserted observer_id"],"identity_processing":{"client_fingerprint":"Transport IP hint + user-agent + optional x-seenrelay-client are privacy-salted and hashed for frictionless lease continuity.","reuse_independence":"Useful-reuse rewards require a different conservative privacy-salted network bucket; x-seenrelay-client and user-agent do not establish reward independence.","observer_key":"Self-asserted IDs and Ed25519 public keys are privacy-salted before application persistence.","caveat":"Pseudonymization reduces exposure; it does not make data anonymous in every legal or contextual sense. Network separation is an anti-farming signal, not proof of unique real-world actors."},"retention":{"observation_rows_days":7,"observer_fact_state_days":7,"hive_lease_operational_retention_days":30,"useful_reuse_event_retention_days":90,"fact_summary":"Retained to support STALE/latest-observed semantics until an explicit deletion/retention policy removes it.","aggregate_daily_metrics":"Retained as operational network measurements unless separately removed."},"submission_boundary":{"intended":"Public or legitimately accessible source-backed operational facts needed by agent workflows.","do_not_submit":["passwords","API keys","access tokens","private cryptographic keys","unnecessary sensitive personal data"],"source_url_hygiene":"Embedded URL credentials and authentication/signature query parameters are rejected. Known tracking parameters and fragments are removed during deterministic canonicalization.","semantic_filtering":"SeenRelay does not use an LLM to inspect or classify submitted values; callers remain responsible for what they submit."},"product_boundary":{"outbound_source_fetch":false,"search":false,"external_verification":false,"llm_truth_oracle":false,"general_agent_memory":false},"environments":{"production_metrics":"Production database only; synthetic Preview/CI traffic must never be represented as traction.","preview_ci":"Dedicated isolated database branch.","reserved_test_namespace_production_guard":true},"endpoints":{"service":"https://seenrelay.com/service.json","data_practices":"https://seenrelay.com/data-practices.json","public_stats":"https://seenrelay.com/public-stats.json"}}